Legal

Privacy Policy

This policy explains what personal data we collect through virtusweb.rs and the client portal, why we collect it, and what rights you have over it.

Last updated:

1. Data controller

The controller of your personal data, under the Serbian Personal Data Protection Act (ZZPL, Official Gazette RS no. 87/2018) and the GDPR, is:

Company
Preduzeće Paktolus d.o.o. Beograd (Savski Venac)
Registered address
Puškinova 2, 11000 Beograd, Srbija
Registration number
20360666
Tax ID (PIB)
105373132
Email
hello@virtusweb.rs

VirtusWeb is the trading name under which the company above operates — contracts and invoices are issued in the company's name. We have not appointed a data protection officer, as we do not meet the criteria in Article 56 of the ZZPL. For any question about how we process data, write to the address above.

2. What this policy covers

This policy covers the public site at virtusweb.rs and the client portal available to signed-in users. It does not cover third-party sites we may link to — those have their own policies.

3. What we collect and on what basis

We collect only what a stated purpose requires, and nothing beyond it.

  • Contact form — your name, email, company name (optional) and the message. Purpose: answering your enquiry and preparing a quote. Legal basis: steps taken at your request prior to entering a contract. The message reaches us by email and is not written to the site's database.
  • User account — name, email, password and the organisation you belong to. Passwords are stored only as a cryptographic hash and cannot be read by us. Legal basis: performance of a contract.
  • Client portal content — projects, invoice items and statuses, files you upload, messages you exchange with us, and time records. Legal basis: performance of a contract, and legal obligation for accounting records.
  • Payment data — if you pay by card, the card details are entered directly with the payment processor (Stripe or NestPay). We never see, process or store them; we receive only the transaction status and what the invoice requires.
  • Technical data — IP address, browser type and version, access time, and application error reports. Legal basis: our legitimate interest in security, debugging and service stability.

4. Cookies

We set only cookies that are strictly necessary, so no consent is required and we show no cookie banner:

  • NEXT_LOCALE — remembers the language you selected.
  • Session cookie — keeps you signed in to the client portal, and is set only after you sign in.

We use no analytics, advertising or cross-site tracking cookies, and no social media pixels.

5. Who processes data on our behalf

We do not sell your data or pass it to third parties for their own purposes. We use the following processors, each strictly for the function listed:

  • Hetzner Online GmbH — server and database hosting, in EU data centres.
  • Cloudflare, Inc. — DNS and traffic protection.
  • Resend (Plus Five Five, Inc.) — sending email, including contact form messages.
  • Functional Software, Inc. (Sentry) — application error reporting and monitoring.
  • Stripe, Inc. and Asseco SEE (NestPay) — card payment processing.

We may disclose data to state authorities where we are legally required to do so.

6. Transfers outside Serbia

The servers holding your data are in the European Union. Some processors (Cloudflare, Sentry, Stripe) may process data outside the EU. Where they do, the transfer relies on standard contractual clauses, in line with Article 65 of the ZZPL.

7. How long we keep data

  • Contact enquiries — up to 12 months after the last exchange, unless the enquiry leads to a contract.
  • Accounts and portal content — for the duration of the business relationship and 12 months after it ends.
  • Accounting records (invoices) — 10 years, as required by Serbian accounting law.
  • Server logs — up to 90 days.
  • Application error reports — up to 90 days.

8. Your rights

In relation to the data we process, you have the right to:

  • access your data and be told how it is processed,
  • have inaccurate data corrected and incomplete data completed,
  • have data erased where there is no longer a basis to process it,
  • restrict processing,
  • receive your data in a structured, commonly used format,
  • object to processing based on legitimate interest,
  • withdraw consent where processing rests on consent, without affecting processing carried out beforehand.

Send your request to hello@virtusweb.rs and we will respond within 30 days at the latest. If you believe your rights have been breached, you may lodge a complaint with the Commissioner for Information of Public Importance and Personal Data Protection, Bulevar kralja Aleksandra 15, 11120 Belgrade, Serbia.

9. Security

All traffic to the site is encrypted (HTTPS/TLS). Passwords are stored hashed, access to data is limited to people who need it to do the work, and systems are patched regularly. No measure is absolute, but we work to keep the risk as low as we can.

10. Children's data

The site and portal are not intended for anyone under 16, and we do not knowingly collect their data. If we learn that we have, we delete it.

11. Changes to this policy

We may update this policy when our services or the law change. The date of the last change is always shown at the top of this page. If a change materially affects how we handle your data, we will tell you by email.

12. Contact

For any question about this policy or to exercise your rights, write to hello@virtusweb.rs.